Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41184

Опубликовано: 28 мая 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the SERVICEACCOUNT_TOKEN placeholder (Canal/Flannel-Calico deployments), the installer substitutes the live Kubernetes ServiceAccount bearer token before logging, exposing the token to any authenticated user with pods/log permission in the namespace with calico-node. The token holds patch privileges on pods/status, enabling annotation-based attacks against cluster workloads. The default kubeconfig-based authentication path is not affected. This is a direct regression of TTA-2018-001.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:*
Версия до 3.21.7 (исключая)
cpe:2.3:a:tigera:calico:*:*:*:*:open_source:*:*:*
Версия до 3.32.0 (исключая)
cpe:2.3:a:tigera:calico:*:*:*:*:cloud:*:*:*
Версия до 22.4.0 (исключая)
cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:*
Версия от 3.22.0 (включая) до 3.22.3 (исключая)

EPSS

Процентиль: 40%
0.00504
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

msrc
2 месяца назад

ServiceAccount token disclosure via install-cni container logs

CVSS3: 6.5
github
2 месяца назад

Calico Inserts Sensitive Information into Log File

EPSS

Процентиль: 40%
0.00504
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-532